QRO. VERIFICADO
Request

Why does ESCODI exist?

Every organization conducting validation processes needs clear, uniform, and verifiable criteria. ESCODI was developed to ensure that all Digital Trust Validations are performed under the same principles, regardless of the evaluated business type.

This allows consistent, transparent processes based on objective evidence.

What does ESCODI represent?

The ESCODI-QRO-001 V1.0 standard establishes the minimum criteria for technical, operational, and legal evaluation used independently by QRO. VERIFICADO. Its purpose is to evaluate the level of digital trust, commercial transparency, the verifiable identity of the issuer, and basic technical security of businesses with an internet presence in the state of Querétaro.

Through this structured framework, safe and localizable commercial navigation is fostered, reducing information asymmetry and strengthening trust between digital consumers and local businesses.

Scope of Applicability

This standard is cross-cutting and can be voluntarily applied to evaluate and validate digital trust signals in:

🏢 Corporate Sites

Portals of companies or service providers presenting their profile, portfolio, and contact methods.

🛒 Online Stores

Websites equipped with a shopping cart, transactional catalogs, and payment gateways (E-commerce).

💻 Service Platforms

Interactive online software, SaaS platforms, and on-demand procedure or service portals.

Validation Evidence

The standard criteria may be accredited through documentary, technical, or functional evidence, depending on the nature of each requirement:

Whenever possible, public or technical verification mechanisms will be preferred over the request for additional documentation. The requested documentation must be proportional to the objective of the evaluated criterion and limited to the strictly necessary to issue an objective result.

Principle of Documentary Proportionality

The documentation required during the evaluation process must directly relate to the criterion it aims to accredit. When a requirement can be verified via technical evidence, public inquiry, or functional validation, this will be preferred over requesting additional documentation.

The Constancia de Situación Fiscal (CSF), licenses, permits, or other official documents may be accepted as accreditation media when pertinent, but they will not constitute the sole valid mechanism unless explicitly required by law or the nature of the criterion.

Hierarchy of Evidence

To guarantee the proportionality of the evaluation process, the standard will utilize the following order of preference to accredit its criteria:

Guiding Principles

The evaluation is guided by six fundamental principles:

⚖️ Legitimacy

The existence of the business and the identity of the solicitor must be verifiable through sufficient evidence in line with the nature of the organization.

👁️ Transparency

The site must provide clear information about its ownership, contact channels, applicable policies, and conditions of operation when applicable.

🔒 Security

The site must implement technical mechanisms that protect the confidentiality, integrity, and availability of information, including the use of HTTPS and basic security controls.

🛡️ Privacy

Personal data processing must comply with current legislation and adopt reasonable measures to protect the information provided by users.

🔍 Objectivity

All evaluations must be based on verifiable technical, documentary, or functional evidence, avoiding subjective criteria.

📂 Data Minimization

During the evaluation process, only the documentation strictly necessary to accredit each criterion of the standard will be requested, prioritizing verification mechanisms that reduce the collection of personal data.

How is the standard applied?

The integration of the standard with the trust ecosystem follows a clear timeline:

ESCODI
Digital Validation
Evaluation
Result
Monitoring

Why does a standard build trust?

When all businesses are evaluated using the same criteria, decisions stop depending on opinions and start depending on verifiable evidence.

⚖️ Uniformity

All processes use exactly the same evaluation criteria.

👁️ Transparency

Criteria are public and can be consulted by anyone.

📋 Consistency

Each validation follows the same methodology regardless of the evaluated business.

📈 Evolution

The standard can be updated to incorporate new technologies and best practices.

"A standard protects both the evaluated business and the consumer because it establishes clear rules before starting any validation process."

Standard Areas of Evaluation

The verification process evaluates compliance structured into five digital trust pillars:

Pillar I Technical Security & Navigation

Verifies that the website infrastructure provides a basic security layer to safeguard user navigation and data transmission:

  • Active and valid SSL certificate: Mandatory SSL/TLS connection encryption.
  • HTTPS navigation: Forced redirection to prevent insecure connections (HTTP).
  • Absence of malware or safety alerts: No critical detections in browsers or web reputation databases.
  • Availability and stable loading: The website must respond adequately to public requests.
Pillar II Identity & Local Operation

Verifies the identity of the solicitor and confirms the actual physical existence and location of the business or independent professional behind the digital platform:

  • Identity and Representation of the Solicitor:

    Objective: Verify who requests the validation and their link to the business.

    Acceptable Evidence: Official identification (INE / Passport) of the legal representative or owner, power of attorney or linking documentation, official emails, corporate records, or other technical or administrative evidence.

  • Physical Location of the Business:

    Objective: Verify that the business operates from a real and verifiable location.

    Acceptable Evidence: Google Maps, Street View, commercial/public records, business directories, photograph of the premises, commercial utility bill (when needed), video call verification, or on-site validation.

Pillar III Verified Contact Methods

Ensures that the visitor has direct and real communication channels with the business, preventing information isolation:

  • Operational telephone line: Telephone number validated via call or active support channel.
  • Support email: Address under its own domain or verified official mailbox with an active response rate.
  • Interactive customer service: Direct messaging, web chats, or forms with prompt responses.
Pillar IV Legal & Regulatory Transparency

Validates strict compliance with basic regulations regarding digital consumer rights and data protection:

  • Mandatory Privacy Notice: Drafted in compliance with the Personal Data Protection Law (LFPDPPP).
  • Terms & Conditions of Use: Clear policies on site use, legal limitations, and commercial scope.
  • Service transparency: Clear statements about service scope, validity, and commitments.
Pillar V Commercial Integrity (E-commerce)

Additional mandatory evaluation criteria exclusive to transactional sites and online stores:

  • Total price transparency: Explicit breakdown of costs, applicable taxes, shipping, and surcharges.
  • Secure payment gateways: Visible integration of certified payment intermediaries (PayPal, Stripe, etc.).
  • Cancellation and return policies: Clear and legible wording of the refund or exchange process.
  • After-sales information: Active channels for tracking purchases, deliveries, and claims resolution.

Application Principles

The criteria defined in this standard are applied based on four foundational principles:

⚖️ Uniformity

All businesses are evaluated under the same criteria and rules, ensuring equal treatment.

🔍 Objectivity

All findings, results, and evaluations are strictly based on technical and documentary evidence.

📂 Traceability

Each validation maintains verifiable history and records on public server dossiers.

📈 Continuous Improvement

The standard evolves dynamically according to emerging technological security challenges.

Results, Evidence, and Validity

Businesses evaluated under the ESCODI-QRO-001 V1.0 standard receive a validation result of Approved, Approved with Observations, or Not Approved. Approved sites obtain their respective Digital Trust Seal, a public record on our servers, a unique validation folio, and a digital validation certificate in PDF backed by a SHA-256 cryptographic signature.

Validation has an ordinary and non-extendable validity of 12 months from its issuance. Upon expiration, a full re-evaluation must be performed to ensure continuous maintenance of the standard policies. Automated monitoring may detect relevant changes in the availability, basic security, and operational status of the validated site.

Standard Government

ESCODI-QRO-001 is part of the technical governance system administered by SGSD and used by QRO. VERIFICADO to conduct Digital Trust Validation processes.

Future versions of the standard will be documented and published as the ecosystem needs evolve.

Limitations and Legal Disclaimer

⚠️ Important Validation Criteria

  • Not a government certification: QRO. VERIFICADO is a commercially independent, private technical evaluation entity. This badge does not replace any permit, license, or authorization from local, state, or federal government authorities.
  • Does not replace legal obligations: It is the sole responsibility of the validated business to comply with all legal, tax, consumer protection (PROFECO), and data protection regulations applicable to its sector.
  • Temporary Guarantee: The seal validates compliance with the criteria defined in this standard only at the time of evaluation and does not exempt the business from future technical incidents, hacks, or bad business practices.

Standard Governance Model

The standard governance structure ensures technical autonomy and consistency:

SGSD
ESCODI
QRO. VERIFICADO
Validations
Verified Businesses

Version History

Historical and current revisions of the ESCODI standard:

Version Release Date Description Status
ESCODI-QRO-001 V1.0 2025-10-15 Initial baseline release of the standard. ✓ Current Active

"A standard builds trust when its criteria are clear, uniform, and applied in a consistent manner."